Thanks, the first problem seems to be fixed now and I created an issue for 
6+7.

That leave me with the problem 2: After logging into any status page I get 
a 401 error, even though the log shows that authorization was successful (I 
get "Executing authorization for expected admin roles [{}]", not followed 
by "User [{}] is not authorized to access the requested resource allowed to 
roles [{}]").

Also, I was looking at LdapAuthenticationProvider and wondered why you are 
adding the attributes as authorities:

authorities.addAll(profile.getAttributes().entrySet().stream().map(e -> new 
SimpleGrantedAuthority(e.getValue().toString())).collect(Collectors.toList()));

That just seems wrong. User attributes are not authorities, only roles are!


Op vrijdag 3 februari 2017 15:25:11 UTC+1 schreef Misagh Moayyed:
>
> Quick update: testing this a bit more I did find a few anomalies. I’ll put 
> aside some time to review and apply fixes and if you want to track 
> progress, do please open up that issue.
>
>  
>
> Thanks.
>
>  
>
> --Misagh
>
>  
>
> *From:* Misagh Moayyed [mailto:[email protected] <javascript:>] 
> *Sent:* Friday, February 3, 2017 2:34 PM
> *To:* [email protected] <javascript:>
> *Subject:* RE: [cas-user] Spring security problems
>
>  
>
>  
>
> 1. I configured security.basic.path=/cas/status/** and it triggers for 
> Spring Boot endpoints (e.g. /cas/status/health), but it doesn't for 
> /cas/status/dashboard. Am I missing a config option somewhere?
>
>  
>
> Possible. Difficult to say without seeing what the config looks like.
>
>  
>
> 2. Are Spring Boot endpoints like /cas/status/health supposed to work?
>
>  
>
> Yes. Open issues if you find the opposite is true.
>
>  
>
> 3. Yes, but if you do that you bypass Spring Security and no longer have 
> to option to validate roles (see https://github.com/apereo/cas/issues/2335
> ).
>
>  
>
> Cool. Sounds like a PR to me.
>
>  
>
> 5. It does need the .type, because LdapAuthenticationProvider uses it.
>
>  
>
> See. See my previous comment.
>
>  
>
> 6. LdapUserGroupsToRolesAuthorizationGenerator is the one that deals with 
> groups, but because it inherits 
> from LdapUserAttributesToRolesAuthorizationGenerator it also checks the 
> roleAttribute (in my code I temporarily moved de roleAttribute code from 
> LdapUserAttributesToRolesAuthorizationGenerator.generate() to 
> addProfileRoles()).
>
>  
>
> If I am understanding you correctly, you’ll need to make sure only 
> LdapUserAttributesToRolesAuthorizationGenerator is activated, and basically 
> treat your groupAttribute as CAS’ roleAttribute if possible.
>
>  
>
>  
>

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/e2c3c303-4a2b-42d1-b16b-556f6181c445%40apereo.org.

Reply via email to